-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Hi Onno,
On Fri, 6 Jun 2014 08:47:32 +0200, Onno Ekker wrote: > Hi, > > Yesterday another OpenSSL was published: > https://www.openssl.org/news/secadv_20140605.txt > > Along with it the security advisory came a fix for servers. > > Enigmail is using GPG, which probably uses OpenSSL, so i think it's > also vulnerable to this issue? > > Which versions of GPG are affected and is there a fix for this on > the client side? The vulnerability only works if both the client > and the server are vulnerable, so if we can fix this on the client > side, we should be safe for all servers, independent of their > state... > > I haven't find about it, and it's probably more a case for a GPG > group, but I'm not subscribed to a GPG group, that's why I ask it > here. > > Onno GPG itself does not contains any OpenSSL components because OpenSSL License is not compatible with GPL. There is a possibility that some libraries or components use OpenSSL. It depends on your system. ex. Gpg4win (gpg2 package for Windows) does not contain OpenSSL. http://lists.wald.intevation.org/pipermail/gpg4win-users-en/2014-April/000962.html http://lists.wald.intevation.org/pipermail/gpg4win-users-en/2014-April/000963.html I think it is better to ask on GnuPG mailing lists. - -- Kosuke Kaizuka <[email protected]> -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.22 (MingW32) iQIcBAEBCgAGBQJTkYoLAAoJEFI91dNOjkjZwTcQAJjX0rttqAlWUDcs1Gn6wg2x Ot3ZuXqprt0SMMkunKibUwDHWsZXBGvkMR9/1BezEhh7DohgCocwwEwzMXoUtMvZ 5HRRDtwj4x9CfpPjo5jUeLqoj1MWsolrWgW0Z+/EzjasZqjf1Q75DgBZCIZF8UVP Q0AdW+Dkf2ergvSOT6A5wQ9GLRwc3MElbEJkHx4nOhcDdquFvIE0+kxz/prbp61W X6j1H/SbR3Pa/WVVUc+baoZw0RJ+40wZwqk8AgTRIgIVZ/Ac7a5D1O/A+8DbMj9s B0DNenNatcxjMCq/7VbpiMGpgU6J1jqLaBahNP36+W9E7fA7Joc7OMtRlnFq9UXa iQQyat8bsx6L/NsLa34me/koLTbyZ1JnYMsAxJSV72Te10saE2xpp4mCdPFivV5R bbZt+3LkxCWJTnqxk2PjW//lIGkYQeQ9OZyCg7cj+5xtzN3fVlb0M60IUKCmUERB cmIp6tSpNVeDc4owUe63aQrI2hmuWLmcRVQ/pQm918rGFG7uZHn/KVMDaoygCCq7 9YzEmXjpc0/jeUdOvJQjJIyzgaJVIEwtXbtRDJxSngWr0FzYParHkXwDsdEnn6Ne WeIWKsP5m4VzyJAREjXQpgk00pGzvTr6o0qAH7mPVCzzus8zd3pDJb1QI33ylDnM nmrST2XYPnYgiO4wbfYl =9ZRJ -----END PGP SIGNATURE----- _______________________________________________ enigmail-users mailing list [email protected] https://admin.hostpoint.ch/mailman/listinfo/enigmail-users_enigmail.net
